CYBERSECURITY

How ransomware has changed

From CryptoLocker through double and triple extortion, and how a business can prepare.

Ransomware attacks now affect 66 percent of organizations worldwide, regardless of size. In 2024 the average ransom demand surpassed $2.5 billion. Attackers are using artificial intelligence to build and deploy ransomware faster. The modern form grew from earlier versions.

CryptoLocker

Ransomware-like attacks go back to the 1980s. Modern ransomware drew wide attention in 2013 with CryptoLocker. That malware used strong encryption to lock files until a ransom was paid. CryptoLocker was taken down in May 2014 in Operation Tovar, a joint effort by international security agencies. They went after the botnet that spread it and recovered a database of private keys, so victims could unlock files without paying. The attacks did not stay quiet after that. Over the following decade they became more complex.

Double and triple extortion

Current ransomware often encrypts files and steals them. Double extortion means encrypting the files and threatening to publish the stolen data if the ransom is not paid.

Triple extortion adds more pressure:

  • Distributed denial-of-service attacks meant to stop the business from operating.
  • Threats against clients or partners, including a threat to expose their data.

AI and ransomware for rent

AI now does work that used to take hours, including generating ransomware code in minutes. On the dark web, criminals can buy ransomware-as-a-service. What that offering includes:

  • Kits that are ready to deploy, with instructions.
  • Subscriptions that include updates and 24/7 technical support for the attackers.
  • Optional upgrades that make the malware more capable.

That lowers the skill required to run a campaign.

What comes next

Ransomware will keep changing. The 2030s may bring another wave. AI may make malware more adaptive and harder to detect, and rental platforms may get easier for less-skilled attackers.

More attacks may hit critical infrastructure such as power grids, hospitals, and water systems, which are often poorly defended and important enough to draw a high ransom.

Deepfakes and AI-written phishing may impersonate an executive or automate the scam, so an employee is tricked into opening a sensitive system.

How a business can prepare

  • Backups that are encrypted and stored offline.
  • Tight access to critical systems, and multi-factor authentication.
  • Managed cybersecurity services are a way for a small business to use specialists.
  • Training so staff recognize phishing and suspicious behavior.
  • Attention to new threats, and defenses adjusted to match them.

Ransomware has moved far past CryptoLocker. Defenses, training, and staying informed are how an organization lowers the risk.

Back to the blog